OpenAI and Google: Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds

OpenAI and Google: Some Mac users think they're installing OpenAI Codex, but it's actually a malware that can steal passwords in seconds

Cybercriminals Exploit Google Sites and Ads to Target macOS Users with AMOS Infostealer

Cybercriminals have launched a sophisticated campaign abusing Google Sites, stolen Google Ads accounts, and OpenAI’s branding to distribute the AMOS infostealer to macOS users. Security researchers at CATO CTRL uncovered the operation, which leverages trusted Google services to appear legitimate while delivering malware.

The attackers created a fake OpenAI Codex download page using Google Sites, avoiding direct malicious content by embedding an iFrame that pulled content from an external source. To drive traffic, they hijacked legitimate Google Ads accounts bypassing automated security checks and ran ads targeting users searching for “codex macos download.” These ads appeared at the top of Google search results, exploiting user trust in Google’s platform.

The fake site mimicked OpenAI’s official download page, featuring Windows and macOS download buttons though only the macOS option was functional. Instead of providing an executable, victims were instructed to paste a Terminal command, a tactic designed to appear authentic, as some AI tools (including OpenAI’s Codex CLI) require Terminal installation.

Once executed, the command deployed AMOS, a macOS infostealer capable of harvesting browser data, login credentials, and cryptocurrency wallet information. The campaign highlights how threat actors abuse trusted platforms and social engineering to bypass security measures and target unsuspecting users.

Source: https://www.techradar.com/pro/security/some-mac-users-think-theyre-installing-openai-codex-but-its-actually-a-malware-that-can-steal-passwords-in-seconds

OpenAI TPRM report: https://www.rankiteo.com/company/openai

Google TPRM report: https://www.rankiteo.com/company/google

"id": "gooope1787668071",
"linkid": "google, openai",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Artificial Intelligence',
                        'name': 'OpenAI (brand impersonation)',
                        'type': 'Technology Company'},
                       {'industry': 'Internet Services',
                        'name': 'Google (platform abuse)',
                        'type': 'Technology Company'},
                       {'customers_affected': 'Unknown',
                        'name': 'macOS Users',
                        'type': 'End Users'}],
 'attack_vector': ['Malvertising',
                   'Social Engineering',
                   'Phishing via Trusted Platforms'],
 'data_breach': {'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Browser data',
                                              'Login credentials',
                                              'Cryptocurrency wallet '
                                              'information']},
 'description': 'Cybercriminals have launched a sophisticated campaign abusing '
                'Google Sites, stolen Google Ads accounts, and OpenAI’s '
                'branding to distribute the AMOS infostealer to macOS users. '
                'The attackers created a fake OpenAI Codex download page using '
                'Google Sites, embedding an iFrame to pull content from an '
                'external source. They hijacked legitimate Google Ads accounts '
                "to run ads targeting users searching for 'codex macos "
                "download,' which appeared at the top of Google search "
                'results. The fake site mimicked OpenAI’s official download '
                'page, tricking users into executing a Terminal command that '
                'deployed AMOS, a macOS infostealer capable of harvesting '
                'browser data, login credentials, and cryptocurrency wallet '
                'information.',
 'impact': {'brand_reputation_impact': ['OpenAI (brand impersonation)'],
            'data_compromised': ['Browser data',
                                 'Login credentials',
                                 'Cryptocurrency wallet information'],
            'identity_theft_risk': 'High',
            'systems_affected': ['macOS']},
 'initial_access_broker': {'entry_point': 'Google Ads and Google Sites'},
 'investigation_status': 'Uncovered by security researchers',
 'lessons_learned': 'Threat actors increasingly abuse trusted platforms like '
                    'Google Sites and Ads to distribute malware, emphasizing '
                    'the need for heightened vigilance and security awareness '
                    'among users. Social engineering tactics, such as fake '
                    'download pages and Terminal commands, can bypass '
                    'traditional security measures.',
 'motivation': ['Financial Gain', 'Data Theft'],
 'post_incident_analysis': {'root_causes': ['Abuse of trusted platforms '
                                            '(Google Sites, Google Ads)',
                                            'Social engineering via fake '
                                            'download pages',
                                            'Lack of user verification for '
                                            'Terminal commands']},
 'recommendations': ['Users should verify the authenticity of download '
                     'sources, especially when prompted to execute Terminal '
                     'commands.',
                     'Organizations should monitor for unauthorized use of '
                     'their branding in malvertising campaigns.',
                     'Google and other platforms should enhance security '
                     'checks for ad accounts and embedded content to prevent '
                     'abuse.'],
 'references': [{'source': 'CATO CTRL'}],
 'response': {'third_party_assistance': 'CATO CTRL (security researchers)'},
 'title': 'Cybercriminals Exploit Google Sites and Ads to Target macOS Users '
          'with AMOS Infostealer',
 'type': 'Infostealer Malware Campaign'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.